Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 18 additions & 1 deletion docs/advanced/error-codes.md
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,9 @@ The route table sends an event to one of these pages, and the entries below name
|---|---|
| [`fluid providers`](../cli/providers.md) | The provider events |
| [`fluid secrets`](../cli/secrets.md) | `copilot_missing_llm_api_key` |
| [Sovereignty](../concepts/sovereignty.md) | The policy and sovereignty events |
| [Sovereignty](../concepts/sovereignty.md) | The policy and sovereignty events, except `policy_compiler_crashed` |
| [`fluid apply`, Iceberg catalog move guard](../cli/apply.md#iceberg-catalog-move-guard) | `iceberg_catalog_move_blocked` |
| [`fluid policy compile`, Errors](../cli/policy-compile.md#errors) | `policy_compiler_crashed` *(unreleased, [forge-cli #710](https://github.com/Agenticstiger/forge-cli/pull/710))* |
| [`fluid verify-signature`](../cli/verify-signature.md) | The signing events |
| [Getting started](../getting-started/README.md) | `opentofu_engine_install_failed` |
| [Typed CLI errors](./typed-cli-errors.md) | The schema-version events and the connectivity events |
Expand Down Expand Up @@ -275,6 +277,14 @@ The state refusals (`state_shared_with_another_provider`, `state_migration_ambig
- If the resources should stay where they are, set the binding's location.region to the region the error names
- If they should move, empty and remove them there first (tofu destroy in the state directory the error names, with AWS_REGION set to the old region), then apply again

### iceberg_catalog_move_blocked

`ERR_ICEBERG_CATALOG_MOVE_BLOCKED`. The documentation link lands on [`fluid apply`, Iceberg catalog move guard](../cli/apply.md#iceberg-catalog-move-guard).

- Run the printed `tofu state rm` commands: they release the resources from this contract's OpenTofu state and touch nothing in the cloud
- Then re-run fluid apply
- The released Glue database/table or Snowflake EXTERNAL VOLUME stays in place; delete it by hand only if nothing else uses it

## Generate

### generate_iac_failed
Expand Down Expand Up @@ -360,6 +370,13 @@ The state refusals (`state_shared_with_another_provider`, `state_migration_ambig

- Check the agent-policy block in the contract; run 'fluid policy check <contract>'

### policy_compiler_crashed

*(unreleased, [forge-cli #710](https://github.com/Agenticstiger/forge-cli/pull/710))* `ERR_POLICY_COMPILER_CRASHED`. The documentation link lands on [`fluid policy compile`, Errors](../cli/policy-compile.md#errors).

- Run 'fluid validate <contract>': policy compile reads accessPolicy and exposes without validating them against the contract schema
- If the contract validates, re-run with 'fluid --log-level DEBUG policy compile <contract>' to see the compiler's traceback

### policy_apply_failed

`ERR_POLICY_APPLY_FAILED`. The documentation link lands on [Sovereignty](../concepts/sovereignty.md).
Expand Down
2 changes: 1 addition & 1 deletion docs/advanced/governance.md
Original file line number Diff line number Diff line change
Expand Up @@ -170,7 +170,7 @@ fluid policy-compile contract.fluid.yaml --out runtime/policy/bindings.json
}
```

`read`-style permissions map to a viewer role and `write`, `insert`, `update` or `delete` to an owner role. A contract with no grants compiles to an empty list and a `No grants found in accessPolicy` warning.
`read`-style permissions map to a viewer role and `write`, `insert`, `update` or `delete` to an owner role. A contract with no grants compiles to an empty list and a `No grants found in accessPolicy` warning. *([forge-cli #710](https://github.com/Agenticstiger/forge-cli/pull/710), unreleased)* Other warnings, such as one for a grant that compiled to no binding, are also printed at WARNING level, and a crash inside the compiler exits `1` with `policy_compiler_crashed` and writes no file. See [Warnings](../cli/policy-compile.md#warnings) and [Errors](../cli/policy-compile.md#errors).

| Option | Description | Default |
|--------|-------------|---------|
Expand Down
2 changes: 1 addition & 1 deletion docs/advanced/production-troubleshooting.md
Original file line number Diff line number Diff line change
Expand Up @@ -107,7 +107,7 @@ Remote OpenTofu state is keyed per contract and provider. See [Environment varia
| `state_migration_unverified` | After the copy, the new key holds different resources than the old one. The old object is untouched | Compare the two states before re-running |
| `state_migration_probe_failed` | The old key could not be read | Check access to the bucket and the key named in the message |
| `opentofu_region_moved` | State holds this contract's resources in a region other than the one the bindings now name. Applying would create them again and leave the originals unmanaged | If they should stay, set the binding's `location.region` to the region the error names. If they should move, empty and remove them there first (`tofu destroy` in the state directory named, with `AWS_REGION` set to the old region), then apply again |
| `iceberg_catalog_move_blocked` | *(unreleased, [forge-cli #707](https://github.com/Agenticstiger/forge-cli/pull/707) and [forge-cli #709](https://github.com/Agenticstiger/forge-cli/pull/709))* An Iceberg expose's `location.catalog` names a catalog an earlier release did not honour, and state still holds what that release created for it: a Glue database on AWS, and the Glue table when the expose names one, or an EXTERNAL VOLUME on Snowflake. The plan would destroy them, and destroying a Glue database deletes every table in it | Run the `tofu -chdir=<module directory> state rm <address>` commands the error prints, which change nothing in the cloud, then apply again. Do not pass `--allow-data-loss`. If the table belongs in Glue or in Snowflake's own catalog, remove `location.catalog` instead. Steps: [Upgrading an AWS contract that names another catalog](./source-aligned-acquisition.md#upgrading-an-aws-contract-that-names-another-catalog), [Upgrading a Snowflake contract that names another catalog](./source-aligned-acquisition.md#upgrading-a-snowflake-contract-that-names-another-catalog) |
| `iceberg_catalog_move_blocked` | *(unreleased, [forge-cli #707](https://github.com/Agenticstiger/forge-cli/pull/707), [forge-cli #709](https://github.com/Agenticstiger/forge-cli/pull/709) and [forge-cli #710](https://github.com/Agenticstiger/forge-cli/pull/710))* An Iceberg expose's `location.catalog` names a catalog an earlier release did not honour, and state still holds what that release created for it: a Glue database on AWS, and the Glue table when the expose names one, or an EXTERNAL VOLUME on Snowflake. The Snowflake volume is named per contract, so it may instead have served a Snowflake-managed Iceberg expose that this change removed or moved to another catalog; the message names both causes. The plan would destroy them, and destroying a Glue database deletes every table in it | Run the `tofu -chdir=<module directory> state rm <address>` commands the error prints, which change nothing in the cloud, then apply again. Do not pass `--allow-data-loss`. If the table belongs in Glue or in Snowflake's own catalog, remove `location.catalog` instead. Steps: [Upgrading an AWS contract that names another catalog](./source-aligned-acquisition.md#upgrading-an-aws-contract-that-names-another-catalog), [Upgrading a Snowflake contract that names another catalog](./source-aligned-acquisition.md#upgrading-a-snowflake-contract-that-names-another-catalog) |
| `iceberg_catalog_move_probe_skipped` (WARNING) | *(unreleased, [forge-cli #709](https://github.com/Agenticstiger/forge-cli/pull/709))* The catalog-move guard could not read the state, or its check failed, so the apply went on without it. The `reason` field says why | If the plan then destroys Glue resources or an EXTERNAL VOLUME of the exposes the warning names, stop: release them with `tofu state rm` and apply again, rather than passing `--allow-data-loss` to the data-loss gate |

## Contract load and overlay errors
Expand Down
Loading
Loading